Table 11: Supported Transforms
(continued)
Description
Transform
IPSec performs ESP protocol encapsulation using the SHA-1 hash function
with HMAC message authentication. SHA-1 is considered stronger than MD5.
ESP-SHA
IPSec performs ESP protocol encapsulation using the DES encryption
algorithm. DES uses a 56-bit symmetric key and is considered a weak
(breakable) encryption algorithm.
ESP-DES
IPSec performs ESP protocol encapsulation using the 3DES encryption
algorithm. 3DES uses a 168-bit symmetric encryption key and is widely
accepted as a strong encryption algorithm. Export control issues apply to
products that ship from the USA with 3DES.
ESP-3DES
Combination of ESP-MD5 and ESP-DES transforms.
ESP-DES-MD5
Combination of ESP-SHA and ESP-DES transforms.
ESP-DES-SHA
Combination of ESP-MD5 and ESP-3DES transforms.
ESP-3DES-MD5
Combination of ESP-SHA and ESP-3DES transforms.
ESP-3DES-SHA
Table 12 on page 131 lists the security functions achieved with the supported transforms,
and provides a view of which combinations can be used, depending on security
requirements.
Table 12: Supported Security Transform Combinations
Supported Transform Combinations
Security Type
AH-HMAC-MD5
AH-HMAC-SHA
ESP-HMAC-MD5
ESP-HMAC-SHA
Data authentication only
ESP-DES
ESP-3DES
Data confidentiality only
ESP-DES-MD5
ESP-DES-SHA
ESP-3DES-MD5
ESP-3DES-SHA
Data authentication and confidentiality
The ISM does not support both the ESP and AH encapsulation modes concurrently on
the same secure tunnel.
131
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...